<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>Website: https://www.ccitic.org&#xA;Linkedin: https://www.linkedin.com/company/ccitic&#xA;X: https://x.com/CCITIC_ORG</description><link>https://bsky.app/profile/ccitic.bsky.social</link><title>@ccitic.bsky.social - CCITIC</title><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mkpiikiyys2s</link><description>🔻 BREACH3D arrested. 15yo, indicted for the ANTS leak — 12-18M records.&#xA;&#xA;10 days after HexDex. Same conclusion:&#xA;&#xA;A pseudonym offers no protection. A forum offers no protection. Being a minor doesn&#39;t erase the process — it shapes it.&#xA;&#xA;🤝 OFAC, BL2C, J3.&#xA;&#xA;#CTI #CCITIC</description><pubDate>30 Apr 2026 11:17 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mkpiikiyys2s</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mkas7jxcr22m</link><description>🚨 CTI — &#34;Imposter&#34; ShinyHunters&#39; private Telegram leaked by NormalLeVrai in retaliation for outing &#34;breach3d&#34;.&#xA;&#xA;341 files / 182.5 MB: full chat, connection metadata, BTC txs via Blockonomics (288f8ef...).&#xA;&#xA;w/ &#34;CyberSatan&#34; seizure = laundering fingerprint.&#xA;&#xA;#CTI #ShinyHunters #CCITIC</description><pubDate>24 Apr 2026 15:01 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mkas7jxcr22m</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mk3azjg4fs2a</link><description>https://www.leparisien.fr/faits-divers/fuite-de-donnees-hexdex-un-hacker-soupconne-de-cyberattaques-massives-interpelle-et-place-en-garde-a-vue-22-04-2026-N6RLLOFNLFHV5HHSFKLX45CYGQ.php</description><pubDate>22 Apr 2026 10:10 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mk3azjg4fs2a</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mjzxjqhouc2f</link><description>🔴 BL2C (Paris Police HQ) &amp; Section J3 of the Paris Prosecutor&#39;s Office have seized the profile of hacker &#34;HexDex&#34;.  &#xA;&#xA;Targeted French public services, companies (Darty, Loxam…) &amp; 10+ sports federations.   &#xA;French-speaking cybercrime is not a lawless space.  &#xA;#CTI #Cybersecurity</description><pubDate>21 Apr 2026 21:48 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mjzxjqhouc2f</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mjznom2t4s2a</link><description>🔴 After HexDex, &#34;Angel_Batista&#34; has also been seized by BL2C (Paris Police HQ) &amp; Section J3 of the Paris Prosecutor&#39;s Office.&#xA;&#xA;Two major French-speaking actors down in a single day.&#xA;&#xA;The message is clear.&#xA;&#xA;#CTI #BreachForums #Takedown</description><pubDate>21 Apr 2026 18:52 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mjznom2t4s2a</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mjrzrsiwls25</link><description>CCITIC&#39;s team now brings together cybersecurity, military intelligence and law enforcement. A complementarity that enables us to act with rigor, within a strict legal framework, for sustained action against cybercrime.</description><pubDate>18 Apr 2026 18:07 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mjrzrsiwls25</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mjpounebkk26</link><description>It&#39;s the weekend, and where&#39;s PwnForums? 👀 &#xA;It looks like they&#39;re having a bit of a rough time at the moment&#xA;pwnforums[.]st</description><pubDate>17 Apr 2026 19:46 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mjpounebkk26</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3miwnvkyvzk2y</link><description>The big clean-up has begun.&#xA;&#xA;BreachForums was merely the tip of the iceberg.&#xA;&#xA;From now on, we go silent. But some threat actors will soon be held accountable.&#xA;&#xA;🔇 No noise. Results.&#xA;⏳ The countdown has started.&#xA;&#xA;— CCITIC</description><pubDate>07 Apr 2026 20:52 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3miwnvkyvzk2y</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mijsupyubs2d</link><description>🔐 First #FIC2026 for CCITIC and it was exceptional! 🔥&#xA;&#xA;Enriching connections, massive projects with our partners to hit cybercrime hard. 💪&#xA;&#xA;Huge thanks to our earliest supporters for the invitation. &#xA;This is only the beginning. ⚡&#xA;&#xA;#CyberSecurity #OSINT #InfoSec #CyberCrime</description><pubDate>02 Apr 2026 18:17 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mijsupyubs2d</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mhyqgay5gc2w</link><description>The truth of BF</description><pubDate>26 Mar 2026 23:18 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mhyqgay5gc2w</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mhw4onr25k22</link><description>Yes, we submitted an abuse report. &#xA;&#xA;No, the hosting provider did not shut down the breachforums[.]ac server. It was simply the server that had been shut down. &#xA;&#xA;We received the confirmation we needed.</description><pubDate>25 Mar 2026 22:19 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mhw4onr25k22</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mhkslr4o3c2v</link><description>#CCITIC</description><pubDate>21 Mar 2026 10:19 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mhkslr4o3c2v</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mhicy6dtss2h</link><description>🔥 When panic switches sides…&#xA;In 1 month, CCITIC has: &#xA;➡️ Taken down BreachForums backend &#xA;➡️ Taken down DarkForums &#xA;➡️ 3 LAPSUS$ takedowns in 9 days &#xA;➡️ Reported their X account&#xA;Abuse reports verified by independent parties.&#xA;🧵👇</description><pubDate>20 Mar 2026 10:34 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mhicy6dtss2h</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mhgqyzg2r223</link><description>💀 DarkForums: down.&#xA;&#xA;After 3 LAPSUS$ takedowns in 9 days &amp; BreachForums&#39; 3 backend servers this weekend…&#xA;&#xA;🔴 Tonight, CCITIC takes down darkforums[.]st&#xA;Error 522 — host server is gone.&#xA;&#xA;💀 LAPSUS$ ✅&#xA;💀 BreachForums ✅&#xA;💀 DarkForums ✅&#xA;&#xA;3 platforms. 1 month. Zero tolerance.&#xA;&#xA;Who&#39;s next? 👀</description><pubDate>19 Mar 2026 19:40 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mhgqyzg2r223</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mhavslf3b224</link><description>1/5&#xA;🔍 BreachForums: not a hack, not maintenance — a takedown.&#xA;Two narratives circulated: LAPSUS$ claimed a hack, BF admin said routine maintenance.&#xA;The reality is far more straightforward. 🧵</description><pubDate>17 Mar 2026 11:50 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mhavslf3b224</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mggf6jglnc25</link><description>On va pas se voiler la face.&#xA;&#xA;Nous avons identifié plusieurs des acteurs s&#39;attaquant à la France et officiant sur BreachForums.&#xA;&#xA;S&#39;attaquer à la santé ou à ceux en charge de notre sécurité ça ne passe simplement pas et ils finiront devant la justice.&#xA;&#xA;Coming Soon !&#xA;&#xA;#CCITIC</description><pubDate>06 Mar 2026 22:43 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mggf6jglnc25</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mgcnujpn3224</link><description>🔴 Third takedown. Nine days. Same group.&#xA;Lapsus$ opened lapsus[.]bz &amp; lapsus[.]by yesterday—both offline this morning.&#xA;&#xA;They are rebuilding. They are being shut down by the CTI community.&#xA;&#xA;Thank you to everyone who contributes to our support.&#xA;👉 www.ccitic.org (SUPPORT)</description><pubDate>05 Mar 2026 11:08 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mgcnujpn3224</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mgadivnylc2a</link><description>Lapsus$ has reopened a site (no, it hasn&#39;t been disclosed yet) but we already have the URL.&#xA;Two domains&#xA;#Lapsus$ #CCITIC</description><pubDate>04 Mar 2026 12:57 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mgadivnylc2a</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mfpnlmvugs2h</link><description>🔴 lapsus.sh is offline.&#xA;&#xA;CCITIC reported the Lapsus$ malicious infrastructure to &#xA;&#xA;Interserver — server successfully taken down.&#xA;&#xA;Thanks Interserver for the quick response. 🤝&#xA;&#xA;Detect. Report. Dismantle.&#xA;&#xA;#ThreatIntelligence #Lapsus #CyberSecurity #CCITIC #OSINT</description><pubDate>25 Feb 2026 21:42 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mfpnlmvugs2h</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3mfnkz5dv2c25</link><description>Official statement from CCITIC on the Lapsus$ case&#xA;https://www.linkedin.com/posts/ccitic_lapsus-cybersecurity-threatintelligence-activity-7432224385958055936-z0qK?utm_source=social_share_send&amp;utm_medium=member_desktop_web&amp;rcm=ACoAAC0Jj5MBcozZ1Yt5RzGz_2j9pLSjAlktPVk</description><pubDate>25 Feb 2026 01:51 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3mfnkz5dv2c25</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3ma7gbpva2k2e</link><description>#CCITIC #Hacker #Cybersecurity #Blackhat #Cybercrime #Infosec</description><pubDate>17 Dec 2025 19:43 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3ma7gbpva2k2e</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3ma7g2vobxc2e</link><description>CCITIC&#xA;‪@ccitic.bsky.social‬&#xA;The news IP of darkforums(.)hn is 185(.)196(.)11(.)58 (proxy)&#xA;hosted by globaldata again !&#xA;The ip redirect to darkforums(.)hn&#xA;&#xA;#CCITIC #Hacker #Cybersecurity #Blackhat #Cybercrime #Infosec</description><pubDate>17 Dec 2025 19:39 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3ma7g2vobxc2e</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3m3pz6l3aws2f</link><description>#CCITIC exclusive =&gt; Information to be verified, but the #Everest ransomware group could potentially be behind or linked to the cyberattack on the Muse software developed by #CollinsAerospace, which paralysed several major airports last month!&#xA;&#xA;#Infosec #Cybersecurity #Cyberattack</description><pubDate>21 Oct 2025 18:58 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3m3pz6l3aws2f</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3m3pyyblslc2f</link><description>#Cybersecurity #Cyberattack #Everest #Hacking #Ransomware #TOR #Offline #ServerOffline #Takedown #Leaks #CollinAerospace #Aviation #Airport #CyberNews #InfoSec #CCITIC #Hacked #Cybercrime #Infosec&#xA;&#xA;Sources:&#xA;https://www.cyberdaily.au/security/12794-exclusive-russia-linked-hackers-claim-responsibility-for-collins-aerospace-hack</description><pubDate>21 Oct 2025 18:54 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3m3pyyblslc2f</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3m2ayffgksk2p</link><description>Update to our report on Datacarry ransomware&#xA;#CCITIC &#xA;#Ransomware #Hacker #Cybersecurity #Threat #Datacarry #Blacksuit #Akira</description><pubDate>03 Oct 2025 02:09 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3m2ayffgksk2p</guid></item><item><link>https://bsky.app/profile/ccitic.bsky.social/post/3ltuj5qatqs2f</link><description>📢 Just out: &#xA;our new #CTI report on the &#xA;#Datacarry #Ransomware group&#xA;&#xA;✏Summary&#xA;📆 11 orgs hit (Jun &#39;24 – Jun &#39;25)&#xA;🛠️ CVE-2023-48788 (Fortinet EMS)&#xA;🕸️ Chisel over WebSocket, solid infra &amp; tooling&#xA;&#xA;💻Full technical breakdown&#xA;https://ccitic.org/assets/reports/CCITIC_Report_TLP-White_DATACARRY.pdf&#xA;&#xA;📄by Kévin Wiart, Hyuna Lee and Rakesh Krishnan</description><pubDate>13 Jul 2025 18:33 +0000</pubDate><guid isPermaLink="false">at://did:plc:qqqlcyp5jwascx2nj3wiawdb/app.bsky.feed.post/3ltuj5qatqs2f</guid></item></channel></rss>